Cybersecurity

Cybersecurity
Denmark CPR Breach Exposes Data of 8.8 Million People
Attackers abused a private firm's lawful lookup rights to pull names, addresses and CPR numbers of 8.8 million people from Denmark's Central Person Register.
Application Security
Atlassian Fixes Critical CVE-2026-21589 in Eight Data Center Products
Atlassian disclosed CVE-2026-21589, a CVSS 9.3 path traversal flaw that lets unauthenticated attackers read web-root files in eight Data Center products.
Cybersecurity
FBI Drops Accenture Contractor After ShinyHunters PeopleSoft Breach
The FBI removed an Accenture contractor over an unapplied patch that let ShinyHunters breach FBIJobs.gov, as a suspected group leader was arrested in Jordan.
Cybersecurity
Nikkei Discloses Microsoft 365 and Google Workspace Account Breaches
Nikkei says attackers breached two employee email accounts, exposed data on 1,646 people and sent about 9,000 phishing emails from a Microsoft 365 account.
Cybersecurity
Ex-Engineer Gets 32 Months for Locking 3,000 Employer Devices
Daniel Rhyne, a former core infrastructure engineer, was sentenced to 32 months for locking over 3,000 devices at a New Jersey firm and demanding 20 ...
Cybersecurity
Senate Passes Health Care Cybersecurity and Resilience Act
The US Senate passed the bipartisan Health Care Cybersecurity and Resilience Act by unanimous consent, sending grants and coordination measures to the House.
Cybersecurity
ClickFix Variant Smuggles Payloads Through Browser Cache
Microsoft Threat Intelligence says a new ClickFix variant hides a script in the browser cache as a PNG, sidestepping the Windows Run dialog's character limit.
CVE Vulnerability Alerts
ClingSTUN Botnet Abuses STUN Protocol for C2, Exploits Dozens of Flaws
FortiGuard and Nozomi detail Cling, a Linux botnet that hides command traffic in STUN requests and exploits about two dozen router and IoT vulnerabilities.
Application Security
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
A critical Rejetto HFS flaw, CVE-2026-61500, lets attackers forge admin session cookies and gain remote code execution; active exploitation began October 1.
Cybersecurity
Citrix Patches New NetScaler Zero-Day Hit by Active Attacks
Citrix released emergency patches for CVE-2026-88779, a NetScaler SAML zero-day under active attack that can knock enterprise login gateways offline for users.